Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
822 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.49% | — | Star-citizen EmbedvideoAI | 15/9/2026 | 30/9/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedServiceFactory::newFromName in includes/EmbedService/EmbedServiceFactory.php interpolates an attacker-controlled unknown… | |
| Aplazada | Alta (7.7) | 0.28% | — | Suprema Biostar XAISupremainc Biostar 2AI | 14/9/2026 | 22/9/2026 | An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request. | |
| Aplazada | Media (5.3) | 0.33% | — | Starlette-adminAI | 12/9/2026 | 23/9/2026 | starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison… | |
| Aplazada | Media (4.3) | 0.25% | — | Starter TemplatesAI | 11/9/2026 | 11/9/2026 | Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions. | |
| Aplazada | Baja (2.1) | 0.37% | — | Starcounter-jack Json-patchAI | 8/9/2026 | 28/9/2026 | A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move Operations. The manipulation leads to improper access controls. Remote exploitation… | |
| Aplazada | Media (5.5) | 0.76% | — | Starcounter-jack Json-patchAI | 7/9/2026 | 8/9/2026 | A flaw has been found in java-json-tools json-patch up to 1.13. Affected is the function JsonMergePatch.fromJson of the file JsonMergePatchDeserializer.java. Executing a manipulation can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. The… | |
| Aplazada | Media (6.9) | 0.41% | — | Lightstar Smartit Desktop ManagerAILightstar Smartit AgentAI | 4/9/2026 | 8/9/2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host. | |
| Aplazada | Crítica (9.3) | 0.63% | — | Lightstar Smartit Desktop ManagerAI | 4/9/2026 | 8/9/2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts. | |
| Aplazada | Alta (8.7) | 0.33% | — | Lightstar Smartit Desktop ManagerAI | 4/9/2026 | 8/9/2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication. | |
| Aplazada | Crítica (9.3) | 0.63% | — | Lightstar Smartit Desktop ManagerAI | 4/9/2026 | 8/9/2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code. | |
| Pendiente de análisis | Alta (8.7) | 0.32% | — | Armorstart LTAI | 1/9/2026 | 1/9/2026 | A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web server. This can result in a loss of web server availability | |
| Pendiente de análisis | Media (6.9) | 0.28% | — | Armorstart LTAI | 1/9/2026 | 1/9/2026 | Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when other users access the affected page. | |
| Aplazada | Baja (1.3) | 0.31% | — | Lognet Grpc-spring-boot-starterAI | 31/8/2026 | 31/8/2026 | A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to improper authorization. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability… | |
| Aplazada | Media (6.5) | 0.55% | — | StarrocksAI | 28/8/2026 | 23/9/2026 | StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfiltered query history for all users. Authenticated attackers with low privileges can access full SQL text, execution plans, and profiling data from every query executed by other users, including… | |
| Aplazada | Media (5.3) | 0.38% | — | StarrocksAI | 28/8/2026 | 23/9/2026 | StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override execute() directly instead of implementing executeWithoutPassword(). Attackers can access six unauthenticated endpoints on the frontend HTTP port to disclose cluster topology, database metadata, JVM… | |
| Aplazada | Media (4.3) | 0.30% | — | Wgstart WgcloudAI | 26/8/2026 | 31/8/2026 | An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concatenated to the ProcessBuilder. | |
| Aplazada | Media (5.4) | 0.45% | — | Starlette AdminAITiangolo FastapiAIEncode StarletteAI | 26/8/2026 | 9/9/2026 | Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applications. Prior to 0.16.1, the list API does not validate user-supplied order_by and structured where field names against the configured sortable_fields and searchable_fields allowlists. An… | |
| Aplazada | Alta (7.1) | 0.53% | — | StarrocksAI | 26/8/2026 | 23/9/2026 | StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every other statement type routed through AuthorizerStmtVisitor calls into Authorizer before execution, but visitDropMaterializedViewStatement returns immediately with a comment stating the check happens in execution logic.… | |
| Aplazada | Alta (7.7) | 0.24% | — | HP Easy StartAI | 24/8/2026 | 3/9/2026 | Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities. | |
| Aplazada | Alta (7.7) | 0.36% | — | HP Easy StartAI | 24/8/2026 | 3/9/2026 | Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities. | |
| Aplazada | Alta (8.5) | 0.30% | — | HP Easy StartAI | 24/8/2026 | 3/9/2026 | Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities. | |
| Aplazada | Media (5.3) | 0.52% | — | Kamalkhan KK Star RatingsAI | 22/8/2026 | 26/8/2026 | The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the software allowing users to execute an action that does not properly validate the 'payload' value before running… | |
| Aplazada | Alta (7.5) | 0.46% | — | Kadencewp Starter TemplatesAI | 18/8/2026 | 20/8/2026 | Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. | |
| Aplazada | Baja (2.1) | 0.35% | — | Spacex Starlink Router GEN 3AI | 16/8/2026 | 20/8/2026 | A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulation leads to improper access controls. The attack can only be initiated within the local network. The exploit has been disclosed to the… | |
| Aplazada | Media (5.3) | 0.16% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 6/8/2026 | 26/8/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending… |